Skip to content

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 03 Oct 20:58
· 38 commits to main since this release
bd5dd2e

A minor: two behaviours change. Mostly security and correctness fixes from a
review of the binding.

Security

  • An untrusted SVG could abort the process. A declared size or a render
    scale large enough made the pixmap allocation fail, which aborts:
    renderAsync('<svg width="200000" height="100000"/>') asked for 80 GB.
    Renders now throw past RenderParams.maxPixels (default 2^28, 1 GiB). #83
  • An untrusted SVG could read local files. usvg's default resolver read any
    absolute href, and relative ones off the working directory, into the
    pixels and the toString() output; /dev/zero exhausted memory. Disk reads
    now need resourcesDir, and stay inside it (canonical path: no .., no
    symlink out). RenderOptions.resourcesRoot widens the fence to an ancestor
    for templates beside a shared assets folder. #83

Behaviour changes

  • Without resourcesDir the disk is not read: an href that resolved off the
    working directory now lands in pendingImages(). Set resourcesDir, or pass
    the bytes as images.
  • width / height are rounded, and throw unless a positive pixel count
    (napi's u32 used to wrap: -1 became 4294967295). A non-finite crop
    throws instead of rendering blank. #84

Fixes

  • FontDatabase.face() / removeFace() with a face from another database
    answered with, or deleted, a face of this one. #84
  • parseAsync enumerated the system fonts on the event loop on first use. #84
  • FontDatabase.query clamps the weight to 1..=1000 instead of truncating. #84
  • The codegen binds only against the upstream version Cargo.lock picked. #85

New

  • Resvg.takeLogs(): a document's own messages, async renders included.
    The module-level takeLogs() still receives everything. #87
  • RenderParams.maxPixels, RenderOptions.resourcesRoot. #83

Performance

  • A FontDatabase is shared with the parses that use it and copied on the first
    write: 0.19 ms -> 0.013 ms per parse with 359 faces. #86

Tooling: @napi-rs/cli 3.10.6 (WASI shims report a crashed worker instead of
hanging, #82), a weekly stale-Cargo.lock probe (#81), CI on notices-only PRs (#80).


What's Changed

  • build(deps-dev): bump @types/node from 26.5.0 to 26.5.1 in the dev-dependencies group across 1 directory by @dependabot[bot] in #58
  • build(deps-dev): bump typescript from 6.0.3 to 7.0.2 by @dependabot[bot] in #59
  • refactor(build): the crate a type comes from is a value, not a chain by @p8nut in #63
  • fix(licenses): the notice ships with the binary it describes by @p8nut in #64
  • refactor(build): a transform is recognised by its shape, not its name by @p8nut in #65
  • feat(build): public means what the crate root exports, re-exports included by @p8nut in #66
  • refactor(build): the crate a path is built from travels with the type by @p8nut in #67
  • build: refresh dependencies, and regenerate the loaders on @napi-rs/cli 3.10.4 by @p8nut in #68
  • build(deps): smallvec 1.16.2, siphasher 1.0.4 by @p8nut in #71
  • fix(licenses): Apache prose is not a copyright holder by @p8nut in #74
  • ci: say why npm ci can never work here by @p8nut in #72
  • build: @napi-rs/cli 3.10.5, and regenerate the WASI shims by @p8nut in #73
  • fix: refuse a signal that is not an AbortSignal by @p8nut in #76
  • ci: fetch the whole crate graph before checking the notices by @p8nut in #79
  • build(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in the dev-dependencies group across 1 directory by @dependabot[bot] in #77
  • ci: keep what a dependabot run regenerates by @p8nut in #75
  • ci: run on pull requests that only touch the third-party notices by @p8nut in #80
  • ci: flag a stale Cargo.lock on the Monday run by @p8nut in #81
  • build: @napi-rs/cli 3.10.6 by @p8nut in #82
  • fix: cap the canvas size and confine image reads to resourcesDir by @p8nut in #83
  • fix: validate render sizes, check face provenance, parse off the loop by @p8nut in #84
  • build: bind only against the sources Cargo.lock picked by @p8nut in #85
  • perf: share FontDatabase with the parses that use it, copy on write by @p8nut in #86
  • feat: per-document logs, Resvg.takeLogs() by @p8nut in #87
  • ci: publish through npm trusted publishing by @p8nut in #89
  • chore(release): 0.4.0 by @p8nut in #88

Full Changelog: v0.3.1...v0.4.0